Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Newgensoft

First CVE: Feb 23, 2010Active for: 16 yearsTotal CVEs: 6

Newgensoft develops a focused portfolio of enterprise document management, e-governance, and business process automation products such as OmniDocs, eGov, OmniApp, and OmniFlow that handle sensitive administrative and organizational workflows. Its vulnerabilities recur through access-control and data-handling weakness classes—improper access control, SQL injection, missing authorization, and resource-transfer issues—that reflect the authentication and database integration demands of document and process management platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Newgensoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2010
16 years ago
Most Recent CVE
Jan 23, 2026
181 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35737HIGH
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka In
Dec 30, 20207.537NOYES
CVE-2011-3645HIGH
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission
Sep 27, 20117.536NOYES
CVE-2025-69908HIGH
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript
Jan 23, 20267.528NONO
CVE-2010-0701HIGH
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Feb 23, 20107.528NOYES
CVE-2025-65742HIGH
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account tak
Dec 15, 20258.225NONO
CVE-2018-17791HIGH
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate i
Aug 21, 20197.523NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network4 (66.7%)
Unknown2 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High0 (0.0%)
Unknown2 (33.3%)
User Interaction
None4 (66.7%)
Unknown2 (33.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (66.7%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Newgensoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Newgensoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Newgensoft's Products

View all 1 CNAs →

Top CWEs